PatchSiren cyber security CVE debrief
CVE-2026-66692 Colissimo CVE debrief
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin, version 2.10.0 and below, contains a Customer Insecure Direct Object References (IDOR) vulnerability. This vulnerability allows unauthorized access to sensitive data or functionality, potentially leading to information disclosure or other security issues. Defenders should verify their inventory and monitor for vendor remediation. The CVE record was published on 2026-08-06T15:17:22.357Z and has not been modified since then.
- Vendor
- Colissimo
- Product
- Colissimo Officiel : Méthodes de livraison pour WooCommerce
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-08
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-08
Who should care
Defenders of WooCommerce installations using Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin should verify their inventory and monitor for vendor remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the potential impact and take necessary actions to protect their systems.
Technical summary
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin, version 2.10.0 and below, has a Customer Insecure Direct Object References (IDOR) vulnerability. This vulnerability allows unauthorized access to sensitive data or functionality, potentially leading to information disclosure or other security issues. The vulnerability is classified as a medium severity issue, with a CVSS score of 4.3.
Defensive priority
Defenders should prioritize verification of affected scope and vendor remediation status.
Recommended defensive actions
- Verify affected scope and inventory
- Monitor for vendor remediation
- Implement compensating controls
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence is limited; primary official records indicate a Customer Insecure Direct Object References (IDOR) vulnerability in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. Defenders should verify their inventory and monitor for vendor remediation. The source details are limited, and further verification is required to confirm the affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66692 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66692
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66692 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66692
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.